Active Zero-Day Exploit Found in Fortinet Email Security Gateway

Fortinet disclosed that attackers are actively exploiting a critical zero-day vulnerability in FortiMail email security appliances, with a severity score of 9.8. The flaw enables unauthenticated attackers to write arbitrary files to affected systems through path traversal and null byte injection attacks. The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its list of known exploited flaws and mandated federal agencies patch by October 4, 2026.
Fortinet identified the vulnerability through its internal security team and disclosed it alongside a critical rating that reflects the severity of the threat. The flaw affects multiple versions of FortiMail spanning several years of releases, from version 7.2 through 8.0, meaning numerous organizations may be running vulnerable software. Patches remain unavailable as of the disclosure date, leaving administrators dependent on temporary mitigation strategies.
The company has provided interim protections while permanent fixes are developed, including disabling the identity-based encryption feature or restricting management interface access to trusted networks. Fortinet has also shared technical indicators of compromise to help administrators determine if their systems have already been attacked, though the company has not disclosed the scale or origins of the active exploitation campaign.
This vulnerability could significantly impact organizations relying on FortiMail for email security, since the flaw allows unauthenticated attackers to write files directly to affected systems without authentication. Email security appliances often sit at critical network boundaries, meaning compromise could provide attackers access to sensitive communications and potential footholds for broader network intrusion. The federal mandate for patching within days suggests government agencies may face particular operational pressure, potentially creating urgency across dependent organizations despite patches not yet being available.